CharonY Posted May 28, 2015 Posted May 28, 2015 I have Avast one computer and while browsing the forums, seemingly at random points I get an infection blocked message. E.g. while clicking on this the biochem link I get: link: http://www.scienceforums.net/forum/14-biochemistry-and-molecular-biology/|{gzip} Infection: HTML:Script-inf Anyone else having these issues?
imatfaal Posted May 28, 2015 Posted May 28, 2015 yes - but it went away before I got around to doing anything about it
MonDie Posted May 28, 2015 Posted May 28, 2015 (edited) I've no real experience, but a man-in-the-middle could inject malicious code. Perhaps check SFN's ping between now and when it gives warnings. That is, if it's allowed. I can't ping it. Edited May 28, 2015 by MonDie
Cap'n Refsmmat Posted May 29, 2015 Posted May 29, 2015 The SFN server doesn't respond to pings, so that wouldn't help. Man-in-the-middle attacks are fairly rare unless you're targeted by the NSA or using dodgy free wifi. The Avast warning sounds like it thinks there's malicious JavaScript on our pages. This is related to the malware warnings we had before. I will try to hunt down the problem further, because apparently it keeps recurring.
Endy0816 Posted May 29, 2015 Posted May 29, 2015 Found this: khundalt.org - scienceforums.net https://isc.sans.edu/forums/diary/Actor+using+Fiesta+exploit+kit/19631/ not sure what steps would need to be taken to clean the forum though. 3
Cap'n Refsmmat Posted May 29, 2015 Posted May 29, 2015 Thanks, that's helpful. I still haven't figured out how the compromise happens, but hopefully I'll find something.
studiot Posted May 29, 2015 Posted May 29, 2015 (edited) I have just returned from my sojurn in Scotland and I am reading this on my Avastpro protected system. Avast see see no problem with SF, although I has reported issues in the past. It is, however, offering a program update (as opposed to a database update). I wonder if the issue is generated by the udated version of Avast. I have seen this on previous occasions with updates. Thank you endy for that highly informative link. +1 The good guys must stick together on this. Edited May 29, 2015 by studiot
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now